ZDI-26-235: Digilent DASYLab DSA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent DASYLab. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-0957.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-235?
The severity of ZDI-26-235 is critical as it allows for remote code execution due to an out-of-bounds write.
How do I fix ZDI-26-235?
To fix ZDI-26-235, update your Digilent DASYLab to the latest version that addresses this vulnerability.
What software is affected by ZDI-26-235?
ZDI-26-235 affects Digilent DASYLab installations.
What is the impact of ZDI-26-235?
The impact of ZDI-26-235 includes the potential for remote attackers to execute arbitrary code on affected systems.
Is user interaction needed to exploit ZDI-26-235?
Yes, user interaction is required as the target must visit a malicious file to exploit ZDI-26-235.